How to connect GSA Internet access to Sophos firewall via site to site VPN for consistent egress IP

William 0 Reputation points
2025-10-22T14:20:05.8866667+00:00

We’ve set up Microsoft Entra Global Secure Access (Internet Access) with a Remote Network and are trying to bring up a site‑to‑site IPsec (route‑based, IKEv2) tunnel from our in‑office Sophos firewall so branch Internet traffic goes through GSA but still presents a single, consistent static egress IP for SaaS apps that use IP allow‑lists. The tunnel/handshake on Sophos is the sticking point (matching GSA defaults: AES‑GCM, DH group 24, PFS none; then BGP over the xfrm interface). What we need: proven Sophos settings or a Microsoft‑supported pattern that keeps SaaS seeing our office static IP. What we don’t want: deploying Private Access connectors/VMs for anchoring, or asking the SaaS vendor to whitelist Microsoft GSA egress IP ranges. Any precise guidance or examples to complete the handshake and preserve static‑IP egress under these constraints would be greatly appreciated.

Microsoft Security | Microsoft Entra | Microsoft Entra Internet Access
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.